The regulatory fact worth carrying, because it is a right and most people do not know they have it. Regulation E, the federal rule governing consumer electronic fund transfers, defines an access device at 12 CFR 1005.2(a)(1) as "a card, code, or other means of access to a consumer's account, or any combination thereof, that may be used by the consumer to initiate electronic fund transfers." A password, a PIN and a one-time code are all access devices, in exactly the same category as the plastic card.
Then 1005.2(m) defines an "unauthorized electronic fund transfer" as one "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit", and excludes from that definition a transfer initiated "(1) By a person who was furnished the access device ... by the consumer, unless the consumer has notified the financial institution that transfers by that person are no longer authorized." Read alone, that carve-out looks fatal for a phishing victim, because they did hand the credentials over.
The official interpretation closes the gap in one sentence. Supplement I to part 1005, comment 2(m)-3, is headed "Access device obtained through robbery or fraud" and reads: "An unauthorized EFT includes a transfer initiated by a person who obtained the access device from the consumer through fraud or robbery." So being tricked out of your credentials is not the same as furnishing them, and the transfer the phisher then makes is unauthorized. The comparison the commentary draws is with comment 2(m)-2, which covers a consumer who "furnishes an access device and grants authority to make transfers to a person (such as a family member or co-worker) who exceeds the authority given", and says that consumer "is fully liable". Granting authority to someone who abuses it is the consumer's problem. Being deceived out of a code is not.
The line this sits on, and the side of it that gives nothing. The whole distinction turns on who initiated the transfer, not on whether the consumer was deceived. Comment 2(m)-3 is about a transfer the thief makes. A transfer the consumer is talked into making themselves is initiated by the consumer and is therefore authorized, however complete the deception, and Regulation E's list of what counts as an "error" contains no limb for inducement. The only comment treating a consumer's own transfer as unauthorized is 2(m)-4, and its trigger is physical force: "An EFT at an ATM is an unauthorized transfer if the consumer has been induced by force to initiate the transfer." So the practical rule is that being deceived into revealing credentials is generally covered, and being deceived into sending the money yourself generally is not. That is the boundary between this page and the pages on fraud and on wire transfers, and it is the single most consequential thing to get right in this area.
The three things a phishing message is trying to do, which is a more useful taxonomy than the channel it arrives on. The first is credential harvesting: a link to a convincing copy of a login page, so the credentials are typed into the wrong site. Where two-factor authentication is in place, the same page will ask for the code, and a real-time operator will use it within its validity window, which is why supplying a code to anyone who asked for it is the point where the account is lost. The second is malware delivery: an attachment or download that installs software able to capture what is typed. The third is payment redirection: no credentials at all, just an instruction to pay a real invoice to a different account, which is the form the closing-table version of the scheme takes.
Only the first two lead to the access-device analysis above. The third produces a payment the consumer made themselves, which is the unprotected side of the line.
Scale, dated and attributed. In the FBI's 2025 Internet Crime Report, phishing and spoofing together were the most frequently reported crime type, with 191,561 complaints, against reported losses of $215,843,126. The comparison worth drawing is with the loss figures for other categories: measured by money, phishing is far from the largest, because it is usually the first step rather than the loss itself. The dollars end up counted under whatever the credentials were then used for.